Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MSUpdate.exe' = '%WINDIR%\WindowsUpdate\MSUpdate.exe'
- User Account Control (UAC)
- %WINDIR%\windowsupdate\msupdate.exe
- %TEMP%\protected.cpp
- %WINDIR%\windowsupdate\ msupdate.exe
- 'localhost':443
- DNS ASK 17.####servicegent.com
- '%WINDIR%\windowsupdate\msupdate.exe'
- '%WINDIR%\windowsupdate\ msupdate.exe'
- '%WINDIR%\windowsupdate\msupdate.exe' ' (with hidden window)